Command Injection Vulnerability in Renovate by RenovateBot
CVE-2026-76233
8.4HIGH
What is CVE-2026-76233?
Versions of Renovate from 39.53.0 and earlier are susceptible to a command injection vulnerability via the gleam manager. This issue arises from the inadequate sanitization of the depName parameter, which is incorporated without safeguards into gleam deps update commands. An attacker with repository write access can exploit this vulnerability by designing malicious gleam.toml files, thereby gaining the ability to execute arbitrary commands on the system that hosts Renovate.
Affected Version(s)
renovate 39.53.0 < 40.33.0
renovate 40.33.0
